Unauthenticated Remote Code Execution in Apache Roller via XML-RPC Deserialization
Apache Roller 6.1.5 is susceptible to unauthenticated remote code execution via insecure Java deserialization on the XML-RPC endpoint, which is triggered by an attacker-supplied 'ex:serializable' extension type before authentication is processed.
CVE search metadata
CVE search record: CVE-2026-82384. Severity: critical. CVSS: 9.8. KEV: no. Product: Apache Roller (6.1.5). Brief: Unauthenticated Remote Code Execution in Apache Roller via XML-RPC Deserialization. Brief link: https://feed.craftedsignal.io/briefs/2026-09-apache-roller-rce/
Apache Roller 6.1.5 contains a critical vulnerability (CVE-2026-82384) allowing unauthenticated remote code execution (RCE) via the application's XML-RPC interface. The vulnerability resides within the XmlRpcServlet, which is configured with the enabledForExtensions=true parameter. This configuration instructs the underlying Apache ws-xmlrpc library to accept vendor-specific extensions, including ex:serializable, which carries base64-encoded Java serialized objects.
Crucially, this deserialization process occurs during the HTTP request handling phase, prior to the enforcement of authentication for Blogger or MetaWeblog APIs. Furthermore, the XML-RPC servlet mapping is active by default in the web.xml configuration, meaning even if an administrator disables XML-RPC via the application's administrative UI, the vulnerable code path remains exposed to unauthenticated exploitation. Attackers can leverage this primitive to achieve full RCE on the host server by providing a crafted gadget chain, typically generated via tools like 'ysoserial'.
Attack Chain
- The attacker performs reconnaissance to identify Apache Roller instances by scanning for standard paths such as
/roller-ui/or/roller-services/xmlrpc. - The attacker fingerprints the application version to confirm the target is running the vulnerable 6.1.5 release.
- The attacker prepares a serialized Java payload using a gadget chain appropriate for the application's classpath (e.g., Commons Collections).
- The attacker crafts an XML-RPC request using the
text/xmlcontent type, embedding the malicious object within anex:serializableextension tag. - The attacker sends a POST request to
/roller-services/xmlrpcor/roller/roller-services/xmlrpc. - The
XmlRpcServletparses the XML body and automatically deserializes the embedded object before reaching the authentication logic. - The deserialization process executes arbitrary code within the context of the JVM process.
- The attacker achieves full control over the application's data and potentially gains a pivot point into the underlying OS.
Impact
Successful exploitation results in full unauthenticated remote code execution with the privileges of the Tomcat or Java application user. This impact includes the complete compromise of blog data, the ability to read or modify sensitive configuration files, and the potential for lateral movement within the environment. The vulnerability has been assigned a CVSS 3.1 score of 9.8, reflecting its high severity and ease of exploitation without user interaction or authentication.
Recommendation
Prioritize the immediate upgrade of all Apache Roller instances to version 6.1.6 or later, which addresses CVE-2026-82384 by disabling extensions and tightening XML-RPC request handling. In environments where immediate patching is not possible, implement WAF or reverse proxy rules to strictly block access to the /roller-services/xmlrpc endpoint for all but known, authorized administrative IP addresses. Security teams should also audit their environments to identify all instances of Apache Roller by searching for common footprints such as the /roller-ui/ directory or specific HTTP response headers.
Immediate actions
Inventory all Apache Roller instances and verify version 6.1.5.
Patch all vulnerable Apache Roller instances to version 6.1.6 or later.
Mitigations
Block access to /roller-services/xmlrpc at the network perimeter or WAF.
CVE-2026-82384
Detection coverage 1
Detects CVE-2026-82384 Exploitation - XML-RPC Deserialization Attempt
criticalDetects exploitation attempts against CVE-2026-82384 by monitoring for POST requests to XML-RPC endpoints containing the ex:serializable extension type.
Detection queries are available on the platform. Get full rules →